[PATCH v2] drm: property: use kzalloc_flex

From: Rosen Penev

Date: Mon Oct 05 2026 - 15:19:08 EST


Store the property values as a flexible array member instead of a
separately allocated array. This removes an allocation and its error
handling.

Add __counted_by for extra runtime analysis. Move the counting variable
assignment to right after allocation as required by __counted_by.

struct drm_property now ends in a flexible array, so move it to the end
of struct drm_damage_mock in the damage helper KUnit test to avoid
-Wflex-array-member-not-at-end.

Assisted-by: LLM
Signed-off-by: Rosen Penev <rosenp@xxxxxxxxx>
---
v2: move test struct member
drivers/gpu/drm/drm_property.c | 14 ++------------
drivers/gpu/drm/tests/drm_damage_helper_test.c | 2 +-
include/drm/drm_property.h | 16 ++++++++--------
3 files changed, 11 insertions(+), 21 deletions(-)

diff --git a/drivers/gpu/drm/drm_property.c b/drivers/gpu/drm/drm_property.c
index f38f2c5437e6..a6008e5c2b58 100644
--- a/drivers/gpu/drm/drm_property.c
+++ b/drivers/gpu/drm/drm_property.c
@@ -107,25 +107,18 @@ struct drm_property *drm_property_create(struct drm_device *dev,
if (WARN_ON(strlen(name) >= DRM_PROP_NAME_LEN))
return NULL;

- property = kzalloc_obj(struct drm_property);
+ property = kzalloc_flex(*property, values, num_values);
if (!property)
return NULL;

+ property->num_values = num_values;
property->dev = dev;

- if (num_values) {
- property->values = kcalloc(num_values, sizeof(uint64_t),
- GFP_KERNEL);
- if (!property->values)
- goto fail;
- }
-
ret = drm_mode_object_add(dev, &property->base, DRM_MODE_OBJECT_PROPERTY);
if (ret)
goto fail;

property->flags = flags;
- property->num_values = num_values;
INIT_LIST_HEAD(&property->enum_list);

strscpy_pad(property->name, name, DRM_PROP_NAME_LEN);
@@ -134,7 +127,6 @@ struct drm_property *drm_property_create(struct drm_device *dev,

return property;
fail:
- kfree(property->values);
kfree(property);
return NULL;
}
@@ -447,8 +439,6 @@ void drm_property_destroy(struct drm_device *dev, struct drm_property *property)
kfree(prop_enum);
}

- if (property->num_values)
- kfree(property->values);
drm_mode_object_unregister(dev, &property->base);
list_del(&property->head);
kfree(property);
diff --git a/drivers/gpu/drm/tests/drm_damage_helper_test.c b/drivers/gpu/drm/tests/drm_damage_helper_test.c
index 0df2e1a54b0d..c0da8dc591a9 100644
--- a/drivers/gpu/drm/tests/drm_damage_helper_test.c
+++ b/drivers/gpu/drm/tests/drm_damage_helper_test.c
@@ -17,10 +17,10 @@ struct drm_damage_mock {
struct drm_device device;
struct drm_object_properties obj_props;
struct drm_plane plane;
- struct drm_property prop;
struct drm_framebuffer fb;
struct drm_plane_state state;
struct drm_plane_state old_state;
+ struct drm_property prop; /* has a flexible array, must be last */
};

static int drm_damage_helper_init(struct kunit *test)
diff --git a/include/drm/drm_property.h b/include/drm/drm_property.h
index aa49b5a42bb5..8c7cef4418c4 100644
--- a/include/drm/drm_property.h
+++ b/include/drm/drm_property.h
@@ -175,14 +175,6 @@ struct drm_property {
*/
uint32_t num_values;

- /**
- * @values:
- *
- * Array with limits and values for the property. The
- * interpretation of these limits is dependent upon the type per @flags.
- */
- uint64_t *values;
-
/**
* @dev: DRM device
*/
@@ -195,6 +187,14 @@ struct drm_property {
* enum and bitmask values.
*/
struct list_head enum_list;
+
+ /**
+ * @values:
+ *
+ * Array with limits and values for the property. The
+ * interpretation of these limits is dependent upon the type per @flags.
+ */
+ uint64_t values[] __counted_by(num_values);
};

/**
--
2.56.0